CVE-2024-30433
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Mar 29, 2024
Updated: Apr 1, 2024
CWE ID 79
Summary
CVE-2024-30433 is a Cross-site Scripting (XSS) vulnerability affecting the MultiVendorX WC Marketplace. The issue, which permits Stored XSS attacks, lies in the improper neutralization of user input during web page generation. This flaw can be exploited by attackers to inject malicious scripts into a webpage viewed by other users, potentially leading to data theft or unauthorized account access. Affected versions of MultiVendorX WC Marketplace include those from n/a through 4.1.3.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share